CVE-2025-69872

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.
Configurations

No configuration.

History

08 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36350 -

30 Jun 2026, 03:17

Type Values Removed Values Added
CWE CWE-502
References
  • () https://access.redhat.com/errata/RHSA-2026:3713 -
  • () https://access.redhat.com/security/cve/CVE-2025-69872 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2439059 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69872.json -

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) DiskCache (python-diskcache) hasta la versión 5.6.3 utiliza Python pickle para la serialización por defecto. Un atacante con acceso de escritura al directorio de caché puede lograr ejecución de código arbitrario cuando una aplicación víctima lee de la caché.

12 Feb 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

11 Feb 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 19:15

Updated : 2026-07-15 02:17


NVD link : CVE-2025-69872

Mitre link : CVE-2025-69872

CVE.ORG link : CVE-2025-69872


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-502

Deserialization of Untrusted Data